<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to disable NAT-T for a specific VPN Tunnel in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/214936#M3784</link>
    <description>&lt;P&gt;Are you seeing / experiencing this on R81.20 or some other version?&lt;/P&gt;
&lt;P&gt;Are all gateways under the same management and what is the topology, is either gateway DAIP?&lt;/P&gt;</description>
    <pubDate>Tue, 21 May 2024 22:32:22 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2024-05-21T22:32:22Z</dc:date>
    <item>
      <title>How to disable NAT-T for a specific VPN Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/214927#M3781</link>
      <description>&lt;P&gt;How to disable NAT-T for a specific VPN Tunnel&lt;/P&gt;&lt;P&gt;Good morning team, I need support because I want to disable NAT-T port 4500 for a specific VPN S2S, as I am having problems with this VPN that is Check point communication with Check point, but every so often we see interruptions and fall of the VPN, at the level of logs we have only found that they are negotiating through NAT-T port 4500 and not throught port 500 which is normal.&lt;/P&gt;&lt;P&gt;I have read a lot of documentation and checkmates but they all say the same thing:&lt;/P&gt;&lt;P&gt;1- NAT-T communication is usually initiated by the peer and checkpoint is only allowed to accept the traffic or not.&lt;BR /&gt;2- NAT-T can be disabled but it is a global configuration that can affect all VPN's.&lt;BR /&gt;3- NAT-T can be changed in the gateway but I understand that this still affects all VPNs connected to this gateway.&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-05-21_12h07_54.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25826i35A28A08AF269576/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2024-05-21_12h07_54.png" alt="2024-05-21_12h07_54.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 18:11:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/214927#M3781</guid>
      <dc:creator>Ks07</dc:creator>
      <dc:date>2024-05-21T18:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable NAT-T for a specific VPN Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/214934#M3782</link>
      <description>&lt;P&gt;In every VPN community there is option to disable NAT for this community. Not sure if this is valid also for NAT-T traffic.&lt;/P&gt;
&lt;P&gt;If you see issue with NAT-T, I would suggest to contact TAC and investigate it.&lt;/P&gt;
&lt;P&gt;NAT-T is used because there is some NAT device in between 2 peers. In order to keep connection in NAT device connection table, Check Point firewall is using NAT-T as keepalive packets every 10 seconds (even if there is no interesting traffic).&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 21:20:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/214934#M3782</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-05-21T21:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable NAT-T for a specific VPN Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/214935#M3783</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1702"&gt;@JozkoMrkvicka&lt;/a&gt;&amp;nbsp;described it perfectly.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 22:30:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/214935#M3783</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-21T22:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable NAT-T for a specific VPN Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/214936#M3784</link>
      <description>&lt;P&gt;Are you seeing / experiencing this on R81.20 or some other version?&lt;/P&gt;
&lt;P&gt;Are all gateways under the same management and what is the topology, is either gateway DAIP?&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 22:32:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/214936#M3784</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-05-21T22:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable NAT-T for a specific VPN Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/214937#M3785</link>
      <description>&lt;P&gt;Great call about DAIP.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 22:43:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/214937#M3785</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-21T22:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable NAT-T for a specific VPN Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/215117#M3786</link>
      <description>&lt;P&gt;NAT-T is normal for a Tunnel if the Gateway is hidden behind a Device that controls the Public IP address.&lt;/P&gt;
&lt;P&gt;With Check Point, there is a Hash Value for NAT-T detection, and if this Hash returns different, then this is a indication that the Tunnel has been NATed behind some other device, thus causing the Tunnel to be made with NAT-T.&lt;/P&gt;
&lt;P&gt;Thus if NAT-T is needed, then NAT-T should not be modified.&lt;/P&gt;
&lt;P&gt;Also, make sure that the Interface you are using for a VPN Tunnel is defined as External interface.&lt;/P&gt;
&lt;P&gt;If you are experiencing Outages,&lt;BR /&gt;Please enable VPN debugs and open a TAC case for further investigation.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 17:36:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/215117#M3786</guid>
      <dc:creator>SenpaiNoticed_U</dc:creator>
      <dc:date>2024-05-23T17:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable NAT-T for a specific VPN Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/215118#M3787</link>
      <description>&lt;P&gt;Check &amp;nbsp;SK177823 to see if that helps. &amp;nbsp;There was a change in a set of Jumbo HFAs a short time ago.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk177823" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk177823&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit:&lt;/P&gt;
&lt;P&gt;Likewise SK32664 has some related info:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk32664" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk32664&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 17:56:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-disable-NAT-T-for-a-specific-VPN-Tunnel/m-p/215118#M3787</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2024-05-23T17:56:27Z</dc:date>
    </item>
  </channel>
</rss>

